There can be many stakeholders involved in defining a SecPlan, including representatives from the:
project, who must deliver the capability (including contractors)
owners of the information to be handled
system users for whom the capability is being developed
management audit authority
CISO, ITSM and system owners
system certifiers and accreditors
information management planning areas
infrastructure management
The GOBISM provides a list of controls that are potentially applicable to a system based on its
functionality and the technology it is implementing. Agencies will need to determine which controls
are in scope of the system and translate those controls to the SecPlan. These controls will then be
assessed on their implementation and effectiveness during an information security assessment as
part of the accreditation process.
8.5.
Standard Operating Procedures (SOP)
Objective:
Recommended Control 1:
Recommended Control 2:
Recommended Control 3:
Standard Operating Procedures (SOPs) ensure security
procedures are followed in an appropriate and repeatable
manner
Agencies should develop separate SOPs for ITSM, system
administrator and system user
The procedures that should be documented in the ITSM, system
administrator and system user‘s SOP are provided in the table
below
ITSMs, system administrators and system users should sign a
statement that they have read and agree to abide by their
respective SOPs
SOPs provide step‐by‐step guides to undertaking information security related tasks and processes.
They provide assurance that tasks can be undertaken in a secure and repeatable manner, even by
system users without strong technical knowledge of the system’s mechanics.
In order to ensure that personnel undertake their duties in an appropriate manner, with a minimum
of confusion, it is important that the roles of ITSMs, system administrators and system users are
covered by SOPs. Furthermore, taking steps to ensure that SOPs are consistent with SecPlans will
reduce the potential for confusion resulting from conflicts in policy and procedures.
32